Usable with caveats: the package is backed by a matching organization repository with tests, changelog, and automated tooling, but it has had no release for over two years and no commits in the last three months. Its low adoption and limited security documentation add maintenance risk.
58%
Total Score
83
100
81
63
One workflow uses pull_request_target, which deserves review because that trigger can expose elevated repository context. However, no untrusted checkout or script-injection pattern was detected, limiting the concern.
The latest release was over two years ago, with no releases in the last 12 months, despite eight releases during its initial development. This is a meaningful sign of slowed maintenance, though the repository is not archived.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this indicates materially slowed maintenance.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy package, but these figures provide little supporting evidence of broad community review or adoption.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap for a package intended to be integrated into applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.45 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.